ai-bom
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents…
Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a
$ npx -y skills add cdxgen/cdxgen --skill sbom-generate --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/sbom-generateContext preview
The summary Claude sees to decide when to auto-load this skill.
Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a
name: sbom-generate description: Generates a CycloneDX SBOM from source code with OWASP cdxgen, covering project-type selection across 30+ ecosystems, monorepo recursion, lifecycle phases, generation profiles, component filtering, and spec-version targeting. Use when asked to create an SBOM or BOM for a repository or directory, produce a dependency inventory, resolve licenses, or export SPDX from source.
Use this skill for the common case: a user wants a CycloneDX SBOM for a repository or directory. For containers and binaries use `container-sbom`; for live hosts use `os-hardware-inventory`; to improve an SBOM that came back thin use `sbom-fidelity-loop`.
Read [reference/safety.md](../../reference/safety.md) before running anything. The dry-run-first rule and the absolute-path rule are not optional.
cdxgen [path] [options]
`path` defaults to `.`. Every boolean flag accepts a `--no-` prefix to invert it.
cdxgen /absolute/path/to/project --dry-run --activity-report json
Summarize what the run would read, write, execute, and fetch. Ask before the real run. Pay particular attention to whether the preview shows package-manager installs; if it does, offer `--no-install-deps` or `--lifecycle pre-build`.
cdxgen /absolute/path/to/project -o /absolute/path/to/bom.json
Auto-detection handles most projects. Reach for flags when it does not.
Omit `-t` and let cdxgen detect. Pass it when detection is wrong, when you want to constrain a large monorepo, or when the target is not source code.
# Restrict a polyglot repo to two ecosystems cdxgen -t java -t python -o /absolute/path/to/bom.json /absolute/path/to/project # Exclude one ecosystem instead of listing the rest cdxgen --exclude-type mcp -o /absolute/path/to/bom.json /absolute/path/to/project
Common aliases (the full matrix is at <https://cdxgen.github.io/cdxgen/#/PROJECT_TYPES>):
| Ecosystem | Types | | ---------- | --------------------------------------------------------------------- | | Node.js | `npm`, `pnpm`, `yarn`, `bun`, `deno`, `js`, `ts`, `nodejs`, `rush` | | JVM | `java`, `kotlin`, `scala`, `groovy`, `gradle`, `maven`, `sbt`, `mill` | | Python | `python`, `uv`, `poetry`, `pdm`, `hatch`, `pixi`, `rye`, `conda` | | Go | `go`, `golang`, `gomod` | | Rust | `rust`, `cargo`, `rs` | | .NET | `csharp`, `dotnet`, `vbnet`, `fsharp` | | Ruby | `ruby`, `bundler`, `gems` | | PHP | `php`, `composer`, `wordpress` | | C/C++ | `c`, `cpp`, `conan`, `collider` | | Others | `dart`, `elixir`, `haskell`, `clojure`, `nix`, `zig`, `gleam`, `mojo` | | CI/config | `github`, `actions`, `helm` |
Pinned toolchains are supported as types too: `java21`, `python312`, `maven3.9.9`, `gradle8.14`, `ruby3.4.0`. cdxgen installs the pinned tool with sdkman and uses it instead of the project's wrapper. This is the fix when a project's wrapper is broken or targets an unsupported JDK.
`--recurse` defaults to `true`. For large repos this is often the wrong default:
# Single project at the root only cdxgen --no-recurse -t java -o /absolute/path/to/bom.json /absolute/path/to/project
Combine `--no-recurse` with explicit `-t` values, or use `--exclude` to skip directories. See <https://cdxgen.github.io/cdxgen/#/MONOREPO>.
| Phase | Behavior | | ------------ | --------------------------------------------------------------- | | `pre-build` | No package installations. Manifests and lockfiles only. | | `build` | Default. May invoke the package manager. | | `post-build` | Binaries and containers rather than source. |
cdxgen --lifecycle pre-build -o /absolute/path/to/bom.json /absolute/path/to/project
`pre-build` is the right choice for CI, containers, air-gapped hosts, and any run where modifying the project is unacceptable.
`--profile` presets a bundle of flags for an intended audience.
| Profile | Intent | | -------------------- | ------------------------------------------------------- | | `generic` | Default | | `appsec` | Application-security review | | `research` | Deep security research, maximum evidence | | `operational` | Operations and runtime inventory | | `threat-modeling` | Threat-model inputs | | `license-compliance` | License resolution and compliance | | `ml` / `ml-deep` / `ml-tiny` | Machine-learning inventory at three depths | | `introspect` | Grade the scan's own fidelity and rank remediations |
cdxgen --profile license-compliance -o /absolute/path/to/bom.json /absolute/path/to/project cdxgen --profile research --evidence -o /absolute/path/to/bom.json /absolute/path/to/project
Use `--profile introspect` when the user's real question is "why is my SBOM incomplete?" — then follow `sbom-fidelity-loop`.
| Flag | Effect | | ------------------- | ----------------------------------------------------------------- | | `--required-only` | Production/non-dev dependencies o
cdxgen is a CLI tool, library, REPL, and server to create, validate, sign, and verify software BOMs. It generates CycloneDX JSON BOMs and supports SPDX 3.0.1 JSON-LD export.
Repo: cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents…
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and…
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with…
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and…
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in…
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF)…